Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-41471

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can more simply upload HTML files containing JavaScript.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.5%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-41471
  • 9001 » Copyparty » Version: 1.9.1
    cpe:2.3:a:9001:copyparty:1.9.1


Contact Us

Shodan ® - All rights reserved